Hybrid Email Policy Device for Cloud Scanning and Local Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security measures face challenges in effectively protecting computer networks from both inbound and outbound email threats, with cloud email services providing limited synchronization of network-specific configurations and separate administrative burdens for inbound and outbound email protections.

Innovation Solution

A communication system that integrates cloud email scanning with local policy application, allowing inbound emails to be scanned by cloud services and evaluated locally, with outbound emails filtered before leaving the network, using an email policy device that applies network-specific policies and reports threats in real-time without storing user configurations elsewhere.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If cloud services are used for email filtering, then bandwidth consumption is reduced, but network-specific policy application and configuration synchronization are limited

Engineering Contradiction:
Improvebandwidth consumptionVSAvoidnetwork-specific policy application
Core Design Contradiction:
Loss of energyVSAdaptability or versatility

Solution Approach 1:

The system divides email filtering into two segments: cloud-based initial filtering (spam, malware) and local policy-based filtering (network-specific rules). This segmentation allows bandwidth savings from cloud filtering while maintaining adaptability through local policy enforcement on inbound and outbound emails.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system merges cloud email filtering services with local on-premise email policy enforcement in a hybrid architecture. The local email policy device receives, sends, and forwards emails while applying network-specific policies, combining the benefits of both cloud and local solutions.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If separate mechanisms are used for inbound and outbound email protection, then comprehensive coverage is achieved, but administrative complexity increases

Engineering Contradiction:
Improveemail protection coverageVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The local email policy device performs multiple functions: receiving inbound emails, sending outbound emails, applying inbound policies, applying outbound policies, and forwarding emails. This multi-functionality provides comprehensive email protection while simplifying administration through a single device interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If cloud scanning is used, then initial threat detection is improved, but real-time local policy enforcement and configuration management are weakened

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidconfiguration management
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system implements feedback by having the local email policy device receive scan results from cloud services and apply local policies based on those results. The local device enforces network-specific policies in real-time and can request additional scanning, creating a feedback loop that maintains both detection accuracy and local control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10171475B2Cloud email message scanning with local policy application in a network environment
Publication Date: 2019.01.01 SKYHIGH SECURITY LLC
  • US10171475B2 patent drawing
  • US10171475B2 patent drawing
  • US10171475B2 patent drawing

AI summary

A method for applying policies to an email message includes receiving, by an inbound policy module in a protected network, message metadata of an email message. The method also includes determining, based on the message metadata, whether receiving the email message in the protected network is prohibited by at least one metadata policy. The method further includes blocking the email message from being forwarded to the protected network if receiving the email message in the protected network is prohibited by the metadata policy. In specific embodiments, the method includes requesting scan results data for the email message if receiving the email message in the protected network is not prohibited by one or more metadata policies. In further embodiments, the method includes receiving the scan results data and requesting the email message if receiving the email message in the protected network is not prohibited by one or more scan policies.